CVE-2023-33299

EUVD-2023-37462
A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port. Note FortiNAC versions 8.x will not be fixed.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
9.6 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
Affected Products (NVD)
VendorProductVersion
fortinetfortinac
8.5.0 ≤
𝑥
≤ 8.5.4
fortinetfortinac
8.6.0 ≤
𝑥
≤ 8.6.5
fortinetfortinac
8.7.0 ≤
𝑥
≤ 8.7.6
fortinetfortinac
8.8.0 ≤
𝑥
≤ 8.8.11
fortinetfortinac
9.1.0 ≤
𝑥
≤ 9.1.9
fortinetfortinac
9.2.0 ≤
𝑥
≤ 9.2.7
fortinetfortinac
7.2.0
fortinetfortinac
7.2.1
fortinetfortinac
8.3.7
fortinetfortinac
9.4.0
fortinetfortinac
9.4.1
fortinetfortinac
9.4.2
𝑥
= Vulnerable software versions